VYPR
Unrated severityNVD Advisory· Published Apr 27, 2006· Updated Jun 16, 2026

CVE-2006-2066

CVE-2006-2066

Description

Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Mkportal/Mkportal2 versions
    cpe:2.3:a:mkportal:mkportal:1.1_rc1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mkportal:mkportal:1.1_rc1:*:*:*:*:*:*:*
    • (no CPE)range: <=1.1 RC1

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.